AdBlock — block ads across the web
The AI review rates the findings as likely false positive, but the risk score (74/100) still counts them.
Analysis record
- Analysed
- Yesterday
- Version
- v6.47.0
- Artifact
- SHA256 B78…B68
- Source
- Findings (non-IoC)
Is AdBlock — block ads across the web safe?
AdBlock blocks ads on YouTube and other sites. The manifest that was scanned declares no special permissions and no host permissions, so the extension works through its background page and content scripts. Its outbound traffic comes from that background page: the scanner logged NET-XMLHTTPREQUEST-abp-background.js-14869 and a series of NET-FETCH entries in the same file, along with NET-FETCH-adblock-functions.js-193 and NET-FETCH-button/header.js-74. Those are the code paths that pull filter lists and refresh subscription data, which is what an ad blocker has to do to keep blocklists current.
Two findings look worse than they are. OBFUSCATION-large_base64 on abp-background.js flags a large embedded base64 blob inside a minified background script, and bundled ad-blocking code carries that kind of inline data. OBFUSCATION-function_indirect in the same file catches indirect call sites that a bundler produces. Neither one points to logic hidden from a reader.
The one high-severity match, YARA--supply_chain_sourcemap_appended_iife, is on abp-background.js.map, the source map that sits beside the compiled script. A source map is a build artifact the browser never runs. The rule fires on the shape of an appended function block in that mapped file, which is how webpack, esbuild and rollup output looks.
Nothing here shows data leaving your browser to a third party, no credential or cookie access, and no code the scan could not read. The matches are the scanner reacting to minified build output and to the network calls that make ad blocking work. That is why this one reads as noise.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
1 rule| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | supply chain sourcemap appended iife | 1 | abp-background.js.map | - |
Publisher Evidence
Limited evidenceAdblock, Inc.
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
YARA Rules Matched
1 ruleAI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
AdBlock for Edge, version 6.47.0, ships a background bundle at abp-background.js and supporting scripts such as adblock-functions.js, adblock-options-support.js, adblock-uiscripts-load_wizard_resources.js, and button/header.js. The manifest metadata in this scan records no permissions and no host permissions. The 408 total findings break down as 386 info-level entries, 21 medium network findings, and one high-severity malware-signature match. Only the nature of those findings is worth weighing.
The one high-severity match is YARA--supply_chain_sourcemap_appended_iife at abp-background.js.map:1. That path is a source map, a build artifact emitted alongside the compiled script and never executed by the browser. Appended IIFEs are the standard output shape of webpack, esbuild, and rollup. A source-map file matching an IIFE-shape rule is a fact about the build pipeline, not a fact about runtime behavior.
The 21 medium network findings are NET-XMLHTTPREQUEST-abp-background.js-14869 and roughly twenty NET-FETCH-* entries in abp-background.js, adblock-functions.js:193, adblock-options-support.js:226, adblock-uiscripts-load_wizard_resources.js:50 and :55, button/header.js:74, and button/help.js:279. An ad blocker fetches filter lists, subscription updates, and UI resources. The file names map to those jobs: adblock-functions.js holds filtering logic, load_wizard_resources.js loads the first-run wizard, button/header.js renders the toolbar button. The scan lists no resolved network endpoints, so there is no domain here to call suspicious.
Two obfuscation entries, OBFUSCATION-large_base64 and OBFUSCATION-function_indirect, both point at abp-background.js:0. An embedded base64 blob and indirect call sites are what a minified background bundle looks like after a build step. Neither entry identifies concealed logic, and the underlying script is readable source in the map.
The strongest counterargument is that a source-map rule tagged to supply chain, plus fetch calls, plus base64 could add up to a package worth distrusting. The rule name mentions supply chain because source maps can be abused to smuggle content into a release, but the match sits on the map file rather than on executed code, and the extension behavior matches its stated job of blocking ads. No credential access, no cookie reads, and no external endpoint appears anywhere in the scan.
What would change this: a resolved endpoint list showing filter-list fetches going somewhere other than the vendor's own infrastructure, or a matched signature inside the runtime bundle rather than the source map. Neither is present, so the evidence points at scanner noise rather than extension misbehavior.
Key Reasons
- Sole high-severity match YARA--supply_chain_sourcemap_appended_iife sits on abp-background.js.map, a non-executed build artifact
- All NET-FETCH and NET-XMLHTTPREQUEST hits are in files named for ad-filtering, wizard loading and toolbar UI, consistent with filter-list fetching
- OBFUSCATION-large_base64 and OBFUSCATION-function_indirect both fire on abp-background.js:0, the expected shape of a minified background bundle
- No resolved network endpoints, no IoCs, no credential or cookie access anywhere in the scan
- The 408-finding total is dominated by 386 info-level entries from bundled vendor scripts
False Positive Considerations
- Source-map build artifact matching a supply-chain YARA rule
- Minified bundled JavaScript flagged as base64 obfuscation and indirect calls
- Ad blocker fetch calls to filter-list and subscription infrastructure
- Info-level finding volume generated by bundled vendor scripts
Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 88%.
Edge version history
Risk trend by version
16 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace